Staff Detection Engineer: SIEM, Cloud & Threat Hunting

LinkedIn

Mountain View (CA)

Hybrid

USD 156,000 - 255,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health and wellness programs
Annual performance bonus
Stock options
Benefits

Job summary

LinkedIn is seeking a Staff Information Security Engineer in Detection Engineering to architect and operate high-signal detections across endpoint, identity, cloud, and SaaS. You will lead strategy, mentor peers, and drive measurable improvements in detection efficacy.

Hybrid role based in Mountain View, with on-site collaboration and flexible work. You will partner with IR, Threat Intel, Cloud, IAM, and Product Security to turn hypotheses into production detections, while maintaining telemetry

Qualifications

  • 5+ years in security engineering, detection engineering, or incident response.
  • 2+ years technical leadership.
  • Expertise with log analytics and detection content for SIEM/XDR/EDR and cloud telemetry (AWS/Azure/GCP).

Responsibilities

  • Define detection strategy and roadmap; drive coverage across priority threat scenarios and emerging attacks relevant to LinkedIn.
  • Partner with IR/Threat Intel/Cloud/IAM to turn hypotheses and TTPs into production detections; lead purple‑team validation.
  • Design detections-as-code with version control, CI/CD, unit/integration tests, and staged rollouts.
  • Lead adversary emulation exercises to validate detection coverage; develop synthetic signal and test harnesses.
  • Proactive threat hunting to discover unknown attacker activity; design hunt playbooks and convert findings into detections.
  • Build IR automation (SOAR/Logic Apps) to orchestrate triage, enrichment, containment, and case workflow.
  • Operationalize threat intelligence: ingest/normalize IOCs/TTPs, enrich detections with TI context, and collaborate with TI to turn reports into testable hypotheses.
  • Build and maintain a SIGMA-based detection content library; translate SIGMA to KQL/SQL where applicable.
  • Own telemetry quality: schemas, enrichment, normalization, and data reliability SLIs/SLOs.
  • Establish and monitor detection quality metrics (signal-to-noise ratio, precision/recall, false‑positive rate, alert latency, lift); drive continuous tuning.
  • Lead incident retros to add resilient post‑incident detections and suppress noisy patterns.
  • Mentor engineers; establish standards, code reviews, and guidance for detection engineering best practices.
  • Participate in on‑call for critical detection pipelines and high‑severity investigations.

Skills

Detection Engineering
Technical Leadership
KQL/SQL
Detection-as-code

Education

BA/BS in CyberSecurity/InfoSec/CS or related

Tools

SIGMA rules
CI/CD tooling
Python scripting

Job description

LinkedIn is seeking a Staff Information Security Engineer in Detection Engineering to architect and operate high-signal detections across endpoint, identity, cloud, and SaaS. You will lead strategy, mentor peers, and drive measurable improvements in detection efficacy.

Hybrid role based in Mountain View, with on-site collaboration and flexible work. You will partner with IR, Threat Intel, Cloud, IAM, and Product Security to turn hypotheses into production detections, while maintaining telemetry

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer, Cloud Security & IR
Detection Engineer, Cloud Security & IR

Intermedia Lab • San Francisco (CA)

On-site
USD 230,000 - 260,000
Competitive cash compensation
Equity
Full benefits
Cyber Detection Engineer: SIEM, Threat Hunting & Cloud
Cyber Detection Engineer: SIEM, Threat Hunting & Cloud

Prudential Financial • Newark (NJ)

On-site
USD 96,000 - 159,000
Market competitive base salaries
Medical, dental, vision
401(k) plan with company match
+4
Security Detection Engineer - Cloud & Identity
Security Detection Engineer - Cloud & Identity

United States Digital Space LLC • Boston (MA)

On-site
USD 130,000 - 170,000
AI-Driven Threat Detection Engineer – SIEM & Cloud
AI-Driven Threat Detection Engineer – SIEM & Cloud

Socket.dev • McLean (VA)

On-site
USD 113,033 - 140,000
Medical, dental, vision insurance
401(k) with company match
Paid time off and holidays
Cloud Security Detection Engineer – IR & Threat Hunting
Cloud Security Detection Engineer – IR & Threat Hunting

IBM • Lowell (MA)

On-site
USD 140,000 - 190,000
Senior SIEM & Detection Engineer (Hybrid)
Senior SIEM & Detection Engineer (Hybrid)

Corebridge Financial • Houston (TX)

Hybrid
USD 168,000 - 195,000
Health insurance
401(k) with company match
Paid time off
+1
Staff Threat Detection & SecOps Engineer
Staff Threat Detection & SecOps Engineer

Envoy Inc. • San Francisco (CA)

On-site
USD 180,000 - 240,000
Security Engineer - Cloud Threat Detection
Security Engineer - Cloud Threat Detection

RoShay Services • Hartford (CT)

Hybrid
USD 140,000 - 210,000
Staff Threat Research Engineer: Detection Innovator
Staff Threat Research Engineer: Detection Innovator

Sumologic • United States

On-site
USD 162,000 - 190,000
Remote Detection Engineer II: Threat Hunting & SOAR
Remote Detection Engineer II: Threat Hunting & SOAR

United States Digital Space LLC • United States

Remote
USD 142,000 - 150,000
Equity grant
Annual refresh grants
Remote-friendly / Flex First